Bitcoin, Ethereum-linked protocols lose $35 million in multiple attacks hours apart
Reported by CoinDesk · AI-assisted summary by ChikoCorp AI News Desk

AI-assisted summary based on the linked source. Verify market-moving details at the original publisher before acting.
In a six-hour period on July 23, 2026, at least three cryptocurrency bridges and cross-chain protocols were exploited in separate attacks that collectively resulted in losses exceeding $35 million. The affected platforms were the Verus Ethereum bridge, the B² Network, and the AFX perpetual exchange bridge on Arbitrum. These incidents highlight recurring vulnerabilities in the design and governance of such cross-chain systems, particularly involving off-chain components like private keys and administrative permissions rather than cryptographic failures.
The Verus Ethereum bridge suffered a $7.54 million loss by exploiting the same contract path and bug class that had been used in a prior $11.5 million attack in May 2026. This flaw allowed the attacker to trigger unbacked Ethereum-side payouts, releasing funds without the corresponding assets locked on the Verus side. After the May incident, most of the stolen funds were returned as part of a bounty arrangement, but these funds were redeposited into the bridge on July 8, exposing the system to another drain two weeks later. Verus’s total value locked has since plummeted from nearly $100 million in early 2025 to about $9 million by mid-2026.
The B² Network lost approximately $3.86 million after an attacker took control of the upgrade authority of its token staking contract, granting the ability to alter contract behavior and drain assets directly. B² responded by suspending staking and committing to compensate affected users. The attacks underscore that the primary causes of significant crypto thefts are compromised permissions and keys rather than flaws in the underlying cryptographic protocols. This vulnerability is becoming more concerning as AI-driven intrusion tools improve, enabling complex, multi-step exploits without human intervention.
Additionally, the AFX perpetual exchange was drained of about $24.15 million through its bridge on Arbitrum, although fewer details about this attack are provided. Security researchers emphasize the importance of auditing not only smart contracts but also the trusted off-chain elements like private keys and administrative controls that can be targeted in these breaches. The repeated failures erode user confidence and threaten the broader ecosystem by exposing how assets can be irreversibly lost when trusted controls are compromised.